CVE-2016-2002: Command Injection
The validateAdminConfig handler in the Analytics Management Console in HPE Vertica 7.0.x before 7.0.2.12, 7.1.x before 7.1.2-12, and 7.2.x before 7.2.2-1 allows remote attackers to execute arbitrary commands via the mcPort parameter, aka ZDI-CAN-3417.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2002?
CVE-2016-2002 has a high severity rating due to its ability to allow remote attackers to execute arbitrary commands.
How do I fix CVE-2016-2002?
To fix CVE-2016-2002, update the HPE Vertica software to version 7.0.2.12, 7.1.2-12, or 7.2.2-1 or higher.
What systems are affected by CVE-2016-2002?
CVE-2016-2002 affects HPE Vertica versions from 7.0.0 to 7.0.2.12, 7.1.0 to 7.1.2-12, and 7.2.0 to 7.2.2-1.
What type of vulnerability is CVE-2016-2002?
CVE-2016-2002 is a remote code execution vulnerability found in the Analytics Management Console of HPE Vertica.
Is CVE-2016-2002 under active exploitation?
At the time of its disclosure, there was no public indication of active exploitation for CVE-2016-2002.